SWIFT MT103 DocuSign Email Scam: Fake Payment Receipt
Written by: Lapain Epuran
Published on:
A SWIFT payment receipt sounds like the kind of document no finance team wants to overlook. Add a familiar electronic-signature layout and a file named “MT103.pdf,” and a fraudulent email can look remarkably close to routine payment paperwork.
The SWIFT MT103 DocuSign email scam is not a transfer confirmation. It uses real financial terminology and copied document-sharing design to steal email login credentials.
Reconstructed example of the fake SWIFT MT103 DocuSign notification. All sender details are fictional.
Overview
This scam impersonates a DocuSign document notification and says a SWIFT payment receipt has been shared with the recipient. The observed email uses the subject “MT103.pdf document has been shared with you via DocuSign” and presents a “Review Document” button.
Clicking the button leads to a counterfeit document portal, not DocuSign. The fake site displays a sign-in prompt and asks for an email address and password. In some versions, the recipient’s address is already filled in from information embedded in the phishing link.
DocuSign and SWIFT are legitimate organizations and are not involved in the attack. Criminals use their names because electronic documents and payment messages are familiar to finance, procurement, and management teams.
SWIFT MT103 DocuSign scam at a glance
Fake claim: A SWIFT MT103 payment receipt is waiting in DocuSign.
Common subject: “MT103.pdf document has been shared with you via DocuSign.”
Visible sender: Often a generic “Finance” name or document-service label.
Call to action: “Review Document.”
Phishing page: A copied document dashboard followed by an email login form.
Information targeted: Email address, password, and potentially multi-factor authentication codes.
Likely impact: Mailbox compromise, payment-thread hijacking, invoice fraud, and theft of confidential business information.
What Is an MT103, and Why Does the Term Matter?
MT103 is real payment terminology. It refers to a standardized SWIFT message used for a single customer credit transfer. Banks and financial teams may use MT103 information when tracing or documenting an international payment.
That technical meaning does not authenticate an email. Anyone can type “MT103” into a subject line or name a fake document “MT103.pdf.” A genuine transfer record must be verified through the bank, payment platform, or established business process, not through branding in an unexpected message.
Technical language creates borrowed authority
Recipients who recognize the term may assume the sender has knowledge of a real transfer. Recipients who do not recognize it may click because the acronym sounds specialized and important.
Either reaction helps the attacker. The email offers just enough information to create interest while withholding the payer, amount, bank reference, and business context that would allow proper verification.
DocuSign branding makes the action feel routine
Electronic-signature notifications commonly ask recipients to review documents. Criminals reproduce the color palette, document card, button, and legal-style footer so the message feels like a standard automated workflow.
DocuSign’s own anti-phishing guidance advises users to examine the destination carefully. Genuine document links use DocuSign-controlled infrastructure, and recipients can access an envelope independently with its security code rather than trusting an unexpected button.
How the SWIFT MT103 DocuSign Email Scam Works
Step 1: The attacker selects payment-facing recipients
The campaign may be sent broadly, but job titles and addresses linked to finance, accounts payable, procurement, logistics, and company leadership are especially attractive. Public websites and professional profiles make many of these addresses easy to identify.
The attacker does not need to know about a real transfer. In organizations that make regular international payments, the lure has a reasonable chance of arriving while someone is expecting financial paperwork.
Step 2: The email claims a receipt was shared
The message says “Finance” sent an MT103 receipt through DocuSign and asks the recipient to review the attached or shared PDF. It may offer a polite invitation to contact the sender with questions.
The language is intentionally neutral. It avoids claims that could be disproved immediately, such as a specific account balance, while still implying that a meaningful payment event occurred.
Step 3: A polished button conceals the link
The “Review Document” button is the core of the attack. The visible design suggests an e-signature service, but the underlying address can point to unrelated object storage, a compromised website, or an attacker-controlled domain.
Never judge a document link by the button text. Preview the destination and compare the registrable domain (the main domain immediately before the top-level suffix) with the provider you expect.
Step 4: A counterfeit dashboard reinforces the story
After the click, the landing page may look like a document viewer with a file card, progress indicator, or sign-in dialog. This additional visual step helps the victim forget that they left the original message.
The copied dashboard is only a web page. A padlock icon means the connection to that page is encrypted; it does not mean the operator is DocuSign or that the page is safe.
Step 5: The page asks the victim to sign in with email
The fraudulent dialog may say “Sign in with other mail” and request both the address and password. A prefilled address can make the form appear connected to the recipient’s organization.
That request is a serious mismatch. Reviewing an electronic document should not require handing an email password to a domain that is not the company’s identity provider or the legitimate document service.
Step 6: Credentials are sent to the criminals
Once submitted, the information is recorded. The page may claim the password was incorrect, show a loading screen, or redirect to a genuine website so the victim assumes the document expired.
Attackers sometimes use the credentials immediately. If they encounter a multi-factor challenge, they may trigger repeated approval notifications or show another fake form for the one-time code.
Step 7: The mailbox is searched for financial opportunities
An accounts mailbox can contain payment instructions, invoices, customer lists, banking contacts, and ongoing transfer conversations. Attackers search these messages to learn the organization’s language and timing.
They can then reply within a genuine thread and substitute their own bank details. Because the response comes from a real account and follows a real conversation, the fraud becomes much harder to spot.
Step 8: The attacker hides and expands access
Criminals may add forwarding rules, create mailbox delegates, authorize a malicious application, or delete warning messages. They may also reset passwords for cloud storage, accounting tools, or other services linked to the email account.
A quick password change is essential, but a complete response must also remove these persistence methods and review what happened while the account was exposed.
Red Flags in the Fake DocuSign Payment Email
There is no verifiable transaction context
A legitimate MT103-related conversation should connect to a known payer, beneficiary, transfer date, bank, or internal reference. A generic receipt arriving without that context is not proof of payment.
The email says “attached,” but only offers a link
Scam messages often mix the language of attachments and shared documents. This inconsistency can reveal that the text was assembled from a template.
DocuSign also warns that its legitimate completion emails do not require recipients to open unexpected Office, ZIP, or executable attachments. Treat any such file as a separate risk.
The destination is not a trusted DocuSign domain
Look at the address bar after navigating only through a safe, independent route. Subdomains can be misleading: a name containing “docusign” at the beginning is still controlled by whatever registrable domain appears at the end.
The page requests the password to your mailbox
A document-service prompt should not ask you to provide an email password directly to an unrelated page. Close the site and use your bank, DocuSign account, or internal payment system independently.
How to Verify the Payment Receipt Safely
Check your internal payment records. Search for the payer, beneficiary, date, and reference through approved systems.
Contact the alleged sender through an existing channel. Use a saved number or earlier verified thread, not the contact details in the suspicious message.
Open DocuSign independently. Sign in from a bookmark or type the official address. If an envelope security code is supplied, use DocuSign’s independent access method.
Ask the bank to confirm the transfer. A bank can verify payment status through established channels; an emailed PDF alone cannot.
Report the message. DocuSign accepts suspected impersonation messages at spam@docusign.com, and your organization’s security team should receive the original email with headers intact.
What to Do if You Have Fallen Victim to This Scam
Change the compromised email password immediately. Use the real identity portal from a trusted bookmark or call your IT desk. Create a unique password that is not used by any other service.
Tell security and finance exactly what happened. Include the time of the click, what information you submitted, whether you approved a login prompt, and whether the mailbox handles payments.
Revoke active sessions and authentication tokens. Administrators should force a global sign-out, revoke refresh tokens, remove unknown OAuth applications, and reset app passwords.
Review multi-factor authentication settings. Remove unfamiliar devices, phone numbers, authenticator methods, passkeys, and backup codes. Do not approve sign-in notifications you did not initiate.
Inspect forwarding rules, delegates, and filters. Attackers often hide payment replies and security alerts. Review server-side rules as well as settings visible in the mail client.
Check financial conversations for tampering. Search recent sent mail, deleted items, and active invoice threads for new banking instructions or altered attachments.
Notify banks and counterparties if payment data was exposed. Ask them to place heightened verification on transfer changes. If money was sent, request an urgent recall or freeze through the bank’s fraud team.
Reset reused credentials. Prioritize accounting software, cloud drives, customer portals, domain registrars, and personal accounts that shared the password.
Preserve evidence and file reports. Save the original message, full headers, landing-page address, sign-in alerts, and transaction details. U.S. organizations can report business email compromise to IC3 and fraud to the FTC.
Scan the device if anything was downloaded. The observed lure focuses on credentials, but related campaigns can deliver malicious files. Run the organization’s approved endpoint scan.
Is Your Device Infected? Run a Free Malware Scan
Slow performance, constant pop-ups, or strange behavior? These are classic signs of a malware infection. The fastest way to find out is to scan your device with Malwarebytes Anti-Malware Free — one of the most trusted malware removal tools available.
The free version detects and removes the most common threats, including:
Adware — the cause of those annoying pop-ups
Browser hijackers — unwanted redirects and changed homepages
Trojans and spyware — hidden programs stealing your data
Potentially unwanted programs (PUPs) — software you never asked for
👉 Select your device below — Windows, Mac, or Android — then follow the simple steps to download Malwarebytes, scan your system, and remove any threats it finds. The whole process takes about 5 minutes.
Malwarebytes for WindowsMalwarebytes for MacMalwarebytes for Android
Run a Malware Scan with Malwarebytes for Windows
Malwarebytes is one of the most popular and trusted anti-malware tools for Windows — and it’s completely free for removing infections. It catches threats that many antivirus programs miss, including adware, browser hijackers, and trojans. Follow the steps below to scan and clean your PC in just a few minutes.
Download Malwarebytes
Click the button below to download the latest version of Malwarebytes for Windows from the official source. The free version is all you need — it will scan your computer and remove adware, browser hijackers, and other malicious software at no cost.
(The link opens in a new page where your download will start)
Install Malwarebytes
When the download finishes, open your Downloads folder and double-click the MBSetup file. If Windows shows a User Account Control pop-up, click “Yes” to allow the installation.
Follow the On-Screen Prompts to Install Malwarebytes
The setup wizard will walk you through a few quick screens:
Choose where you’re installing the program — “Personal Computer” or “Work Computer” — then click Next.
Malwarebytes will now install on your device. This usually takes under a minute.
When installation is complete, the “Welcome to Malwarebytes” screen will open automatically.
On the final screen, click Open Malwarebytes to launch the program.
Enable “Scan for Rootkits”
Before scanning, turn on rootkit detection so Malwarebytes can find even the most hidden threats. Click the Settings gear icon on the left side of the screen.
In the settings menu, find “Scan for rootkits” and click the toggle so it turns blue.
Done? Click “Dashboard” in the left pane to return to the main screen.
Start the Scan
Click the blue Scan button. Malwarebytes will automatically update its virus database and start checking your computer for malware.
Wait for the Scan to Finish
The scan checks your entire system for browser hijackers and other malicious programs, so it can take several minutes. Feel free to do something else — just check back occasionally to see the progress.
Quarantine the Detected Threats
When the scan is done, you’ll see a list of everything Malwarebytes found — malware, adware, and potentially unwanted programs. Click the “Quarantine” button to remove all of them at once.
Malwarebytes will now remove the malicious files and registry entries and move them safely into quarantine.
Restart Your Computer
Some threats can only be fully removed after a reboot. If Malwarebytes asks you to restart, click Yes. Once you’re logged back in, your PC is clean and you can continue with the next steps in this guide.
When the scan finishes, click Quarantine to remove everything Malwarebytes found. That’s it — your Windows PC is now clean of trojans, adware, and other malware, and should be back to running smoothly.
If your current antivirus allowed this malicious program on your computer, you may want to consider purchasing Malwarebytes Premium to protect against these types of threats in the future. If you are still having problems with your computer after completing these instructions, then please follow one of the steps:
Malwarebytes for Mac is a free on-demand scanner that removes the malware other security software tends to miss — adware, browser hijackers, and unwanted programs included. Cleaning an infected Mac with Malwarebytes has always been completely free, and it’s our go-to recommendation. Follow the steps below to scan and clean your Mac in just a few minutes.
Download Malwarebytes for Mac
Click the button below to download the latest version of Malwarebytes for Mac.
When the download finishes, open your Downloads folder and double-click the setup file to begin the installation.
Follow the On-Screen Prompts to Install Malwarebytes
The Malwarebytes for Mac Installer will guide you through a few quick screens. Click “Continue” and keep following the prompts until the installation completes.
When the installation is complete, Malwarebytes opens to the Welcome to Malwarebytes screen. Click “Get started“.
Select “Personal Computer” or “Work Computer”
Malwarebytes will ask what type of computer you’re installing it on. Click either Personal Computer or Work Computer, whichever applies.
Start the Scan
Click the “Scan” button. Malwarebytes will automatically update its detection database and begin checking your Mac for malware.
Wait for the Scan to Finish
Malwarebytes will scan your Mac for adware, browser hijackers, and other malicious programs. This can take a few minutes, so feel free to do something else — just check back occasionally to see the progress.
Quarantine the Detected Threats
When the scan is done, you’ll see a list of everything Malwarebytes found. Click the “Quarantine” button to remove all the threats at once.
Restart Your Mac
Malwarebytes will now remove all the malicious files it found. Some threats can only be fully removed after a reboot — if Malwarebytes asks you to restart, allow it. Once you’re logged back in, your Mac is clean.
Once the scan is done, remove every threat it detected. Your Mac is now free of adware, rogue browser extensions, and other potentially harmful software.
If your current antivirus allowed a malicious program on your computer, you might want to consider purchasing the full-featured version of Malwarebytes Anti-Malware to protect against these types of threats in the future. If you are still experiencing problems while trying to remove a malicious program from your computer, please ask for help in our Mac Malware Removal Help & Support forum.
Run a Malware Scan with Malwarebytes for Android
Malwarebytes for Android automatically detects and removes dangerous threats like malware and ransomware so you don’t have to worry about your most-used device being compromised. Aggressive detection of adware and potentially unwanted programs keeps your Android phone or tablet running smooth.
Download Malwarebytes for Android.
You can download Malwarebytes for Android by clicking the link below.
In the Google Play Store, tap “Install” to install Malwarebytes for Android on your device.
When the installation process has finished, tap “Open” to begin using Malwarebytes for Android. You can also open Malwarebytes by tapping on its icon in your phone menu or home screen.
Follow the on-screen prompts to complete the setup process
When Malwarebytes will open, you will see the Malwarebytes Setup Wizard which will guide you through a series of permissions and other setup options. This is the first of two screens that explain the difference between the Premium and Free versions. Swipe this screen to continue. Tap on “Got it” to proceed to the next step. Malwarebytes for Android will now ask for a set of permissions that are required to scan your device and protect it from malware. Tap on “Give permission” to continue. Tap on “Allow” to permit Malwarebytes to access the files on your phone.
Update database and run a scan with Malwarebytes for Android
You will now be prompted to update the Malwarebytes database and run a full system scan.
Click on “Update database” to update the Malwarebytes for Android definitions to the latest version, then click on “Run full scan” to perform a system scan.
Wait for the Malwarebytes scan to complete.
Malwarebytes will now start scanning your phone for adware and other malicious apps. This process can take a few minutes, so we suggest you do something else and periodically check on the status of the scan to see when it is finished.
Click on “Remove Selected”.
When the scan has been completed, you will be presented with a screen showing the malware infections that Malwarebytes for Android has detected. To remove the malicious apps that Malwarebytes has found, tap on the “Remove Selected” button.
Restart your phone.
Malwarebytes for Android will now remove all the malicious apps that it has found. To complete the malware removal process, Malwarebytes may ask you to restart your device.
After the scan, tap Remove Selected to delete all detected threats. Your Android phone is now clean — no more malicious apps, adware, or browser redirects.
If your current antivirus allowed a malicious app on your phone, you may want to consider purchasing the full-featured version of Malwarebytes to protect against these types of threats in the future. If you are still having problems with your phone after completing these instructions, then please follow one of the steps:
Restore your phone to factory settings by going to Settings > General management > Reset > Factory data reset.
Now that your device is clean, keep it that way. Most infections start with a malicious ad or a fake download button — so blocking them at the source is your best defense.
We recommend AdGuard, which blocks malicious ads, phishing pages, and dangerous redirects before they can reach you.
How to Protect Finance Teams From Payment-Document Phishing
Verify payments outside email
Require employees to confirm transfer documents through a bank portal, ERP system, or known contact. A PDF, screenshot, or DocuSign-style notification should support an existing payment record, not create one by itself.
Changes to beneficiary details should require a callback and dual approval. The verification contact must come from trusted records, never from the message requesting the change.
Use stronger identity controls
Passkeys or hardware security keys reduce the value of passwords captured by phishing pages. Combine them with device-based access policies, alerts for new inbox rules, and monitoring of impossible or unusual sign-ins.
Teach staff to read domains from right to left
Attackers place trusted words inside long subdomains. Employees should identify the real registrable domain near the end of the hostname and compare it with the organization they expect.
That small habit is more reliable than judging a logo, button color, padlock icon, or page title.
Common Questions About the MT103 DocuSign Scam
Does an MT103 prove that money reached the beneficiary?
An MT103 is a real SWIFT payment message, but a screenshot or PDF in an email can be altered or fabricated. Payment status must be confirmed with the relevant bank and matched to the correct accounts, amount, date, and transaction reference.
Do not release goods, refund an alleged overpayment, or change an order solely because an emailed document carries an MT103 label.
Can a real DocuSign notice arrive unexpectedly?
Yes, legitimate people can send DocuSign envelopes without a previous email. Unexpected does not automatically mean fraudulent, but it means the sender and document should be verified before you sign in, download files, or disclose information.
Is moving the message to my inbox a real fix?
Some scam copies tell recipients to move the email from Junk to Inbox if the document fails to open. That instruction can reduce protective warnings or make a future click easier. Moving a message does not authenticate its sender or repair a legitimate document.
What if I reviewed the fake page but submitted nothing?
Report the link and check for unexpected downloads. If you did not enter credentials, approve a prompt, or run a file, an account takeover is less likely. Still review recent security alerts because a prior session or automatic redirect may have behaved differently than expected.
Finance teams should retain the original payment request and compare the alleged receipt with the beneficiary instructions approved before the transfer.
If the sender introduces urgency, a new beneficiary, or a request to return an “overpayment,” stop and ask the bank to verify the situation. Fraudsters can use a fake receipt to obtain goods or persuade a victim to refund money that never arrived.
“MT103” is legitimate banking terminology, and DocuSign is a legitimate service, but combining two trusted names does not make an unexpected email genuine. This campaign uses both to push recipients toward a counterfeit dashboard and an email-password form.
Verify the transfer through the bank and open document services independently. If credentials were entered, treat the mailbox as compromised: revoke sessions, inspect rules, secure payment workflows, and warn any counterparties who could receive fraudulent instructions.
10 Rules to Avoid Online Scams
Here are 10 practical safety rules to help you avoid malware, online shopping scams, crypto scams, and other online fraud. Each tip includes a quick “if you already got hit” action.
Stop and verify before you click, log in, download, or pay.
Most scams win by creating urgency. Verify using a trusted method: type the website address yourself, use the official app, or call a known number (not the one in the message).
If you already clicked: close the page, do not enter passwords, and run a malware scan.
Keep your operating system, browser, and apps updated.
Updates patch security holes used by malware and malicious ads. Turn on automatic updates where possible.
If you saw a scary “update now” pop-up: close it and update only through your device settings or the official app store.
Use layered protection: antivirus plus an ad blocker.
Antivirus helps block malware. An ad blocker reduces scam redirects, phishing pages, and malvertising.
If your browser is acting weird: remove unknown extensions, reset the browser, then run a full scan.
Install apps, software, and extensions only from official sources.
Avoid cracked software, “keygens,” and random downloads. During installs, choose Custom/Advanced and decline bundled offers you do not recognize.
If you already installed something suspicious: uninstall it, restart, and scan again.
Treat links and attachments as untrusted by default.
Phishing often impersonates delivery services, banks, and popular brands. If it is unexpected, do not open attachments or log in through the message.
If you entered credentials: change the password immediately and enable 2FA.
Shop safely: research the store, then pay with protection.
Be cautious with brand-new stores, “closing sale” stories, and prices that make no sense. Prefer credit cards or PayPal for dispute options. Avoid wire transfers, gift cards, and crypto payments.
If you already paid: contact your card issuer or PayPal quickly to dispute the transaction.
Crypto rule: never pay a “fee” to withdraw or recover money.
Common patterns include fake profits, then “tax,” “gas,” or “verification” fees. Another is a “recovery agent” who demands upfront crypto.
If you already sent crypto: stop paying, save evidence (wallet addresses, TXIDs, chats), and report the scam to the platform used.
Secure your accounts with unique passwords and 2FA (start with email).
Use a password manager and unique passwords for every account. Enable 2FA using an authenticator app when possible.
If you suspect an account takeover: change passwords, sign out of all devices, and review recent logins and recovery settings.
Back up important files and keep one backup offline.
Backups protect you from ransomware and device failure. Keep at least one backup on an external drive that is not always connected.
If you suspect infection: do not connect backup drives until the system is clean.
If you think you are a victim: stop losses, document evidence, and escalate fast.
Move quickly. Speed matters for disputes, account recovery, and limiting damage.
Stop payments and contact: do not send more money or respond to the scammer.
Call your bank or card issuer: block transactions, replace the card if needed, and start a dispute or chargeback.
Secure your email first: change the email password, enable 2FA, and remove unfamiliar recovery options.
Secure other accounts: change passwords, enable 2FA, and log out of all sessions.
Scan your device: remove suspicious apps or extensions, then run a full malware scan.
Save evidence: screenshots, emails, order pages, tracking pages, wallet addresses, TXIDs, and chat logs.
Report it: to the payment provider, marketplace, social platform, exchange, or wallet service involved.
These rules are intentionally simple. Most online losses happen when decisions are rushed. Slow down, verify independently, and use payment methods and account controls that give you recourse.
Hello! I'm Lapain Epuran, your go-to source for detailed and honest product reviews. From tech gadgets to miracle cures, I provide insights to help you make informed choices. Join me as we discover what's truly worth your time and money.